In this article you will learn how roles, permissions and facility access work together, how to adjust the permissions of a role and how to give an employee access to the right facility:
Contents
- Roles, Permissions and Facility Access
- Select Roles
- Search and Adjust Permissions
- Save Changes
- Facility Access
- Rules and Limits of Facility Access
- When a Change Takes Effect
- Troubleshooting
- Related Articles
Quick Guide
- Go to Resources / Employees / Roles and select the role you want to change.
- Search for the permissions you need and enable them with their checkboxes.
- Save your changes.
- Go to Resources / Employees / Overview and open the employee.
- In the Access data card, check under Facilities that the employee holds this role at every facility where they need it. Use Edit facility access or Create facility access to correct it.
- Have the employee log in again.
Detailed Instructions
Roles, Permissions and Facility Access
Permissions are never granted to a single employee directly. They are collected in a role, and the role is assigned to an employee for one or more facilities. Two separate settings therefore have to be right before an employee can work with a feature:
| What it controls | Where you set it |
|---|---|
| The role, meaning which permissions the bundle contains | Resources / Employees / Roles |
| The facility access, meaning at which facilities an employee holds that role | The employee record, Access data card |
Permissions are resolved per facility. A permission that is enabled in the role but not backed by facility access does nothing: the employee sees no data for that facility, even though the checkbox in the role is set. Check both sides before you look for any other cause.
There is also no single setting that covers a whole chain. Facility access is always a list of facilities, and an employee can hold a different role at each of them.
For the roles that are preconfigured in the software and for creating your own, see Employee roles. For the difference between a permission and a competence, see Differences between Permission and Competences.
Select Roles
Open Resources / Employees / Roles. Here you will find a list of all available roles in your system. The screen is permission-gated itself: if you cannot see the entry, your own role does not include the permission for employee roles.
Search and Adjust Permissions
Select the role you want to change. Its permissions are spread over category tabs, for example Employees & Resources. Inside a tab the permissions sit under group headers that carry the number of permissions in the group. In the Employees & Resources tab these are Employee Management (13), Resources (2), Roles (1), Shift planning (6) and Time tracking (6). Some groups are split further into subcategories, for example Administration, which holds the permissions for member master data.
A group header is not a permission. It has no checkbox and cannot be switched on. Only the individual entries below it can be enabled, so it is easy to hunt for a toggle that is only a heading.
A single system holds several hundred permissions, which is why the search field above the list is usually faster than working through the tabs. Examples of what you can search for:
- Manage member activities
- Manage contact details
- Manage leads
Enable the required permissions by checking the corresponding boxes. To see what the role grants today, switch the list to Only show granted permissions.
Save Changes
Nothing is stored until you save. As soon as you change a checkbox the editor offers a save banner, so confirm it before you leave the screen, otherwise the change is discarded. When the change reaches the employee is a separate question, see When a Change Takes Effect.
Facility Access
Facility access is maintained on the employee record, not on the roles screen:
- Go to Resources / Employees / Overview and click the name of the employee.
- On the employee record, open the Access data card in the right column.
- The Facilities row lists every facility the employee has access to, together with the role held there.
- Open the menu icon at the end of a row and select Edit facility access to change the assignment, or Delete facility access to remove it.
- The dialog that opens shows an expandable facility selector with the number of selected facilities and the Role in facility dropdown. Select the facilities, choose the role and save.
If the employee has no assignment yet, use Create facility access instead. Use the same action when an employee needs a different role at a further facility: editing an existing entry only changes the facility set of that one assignment, so a second role needs a second facility access.
One note on wording: the card, the list heading and the menu entries all use Facility and Facilities. The word Location is still in use elsewhere in the same flow, for example the sidebar module Resources / Locations and the type-ahead placeholder Select location inside the dialog. Both terms refer to the same thing.
Rules and Limits of Facility Access
- Editing needs its own permission. If a row offers no menu, your own role is missing the permission to change the access data of employees.
- Every facility keeps at least one active admin. The software refuses to remove the last one and shows an error message instead. Give the admin role to somebody else first, then remove it from the original employee.
- The role dropdown only offers matching roles. A role appears under Role in facility only if it is available at the facilities you selected. If a role you expect is missing, check the facility selection first.
When a Change Takes Effect
Two cases behave differently, and it helps to keep them apart:
- You change the role or the facility access of an employee. The software logs that employee out automatically once you have saved the change. The new assignment applies at their next login.
- You switch a single permission inside a role the employee already holds. This change takes effect immediately. The employee does not need to log out and log back in.
Troubleshooting
If an employee still cannot do what you expect, work through these four questions in order:
- Does the role contain the permission? Open the role and check the entry, or use Exporting User Roles and Permissions for Documentation and Analysis to see everything a role grants in one place.
- Does the employee hold that role at the facility they are working in? Check the Facilities row in the Access data card.
- Has the employee logged in again since the change?
- Is something other than a permission hiding the data? A permission can be correct while a filter, a view setting or a calendar configuration still hides what the employee is looking for. The articles for the individual areas cover those cases.
If the employee cannot log in at all, this is a different problem: see How can I resolve issues with employee login and access?. If the problem persists, please contact support for further assistance.